Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243340 > unrolled thread
| Started by | rhkramer@gmail.com |
|---|---|
| First post | 2021-12-21 20:00 +0100 |
| Last post | 2021-12-22 21:50 +0100 |
| Articles | 18 — 6 participants |
Back to article view | Back to linux.debian.user
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 20:00 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-22 15:20 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-22 19:50 +0100
Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-22 20:00 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-22 20:30 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-22 20:10 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-22 20:20 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-23 14:10 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-23 15:10 +0100
Re: Identity Theft harryweaver@tutanota.com - 2021-12-23 21:40 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-23 22:10 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-23 22:30 +0100
Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-24 00:50 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-24 16:00 +0100
Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-24 16:20 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-24 16:30 +0100
Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-24 16:40 +0100
Re: Identity Theft harryweaver@tutanota.com - 2021-12-22 21:50 +0100
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-21 20:00 +0100 |
| Subject | Re: Identity Theft |
| Message-ID | <DwSwF-3fj-1@gated-at.bofh.it> |
On Tuesday, December 21, 2021 12:46:35 PM rhkramer@gmail.com wrote: > What kind of phone did you use to make the call -- I mean cell phone, POTS, > VOIP phone, or maybe something else? Ahh, darn, sorry for the noise -- on first reading I missed the part about a cell phone. That is a known thing (a telephone intercept of a cell phone call), I have found nothing so far about such a thing happening with a VOIP phone or land line.
[toc] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-12-22 15:20 +0100 |
| Message-ID | <DxaDf-61V-1@gated-at.bofh.it> |
| In reply to | #243340 |
On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > That is a known thing (a telephone intercept of a cell phone call), I have > found nothing so far about such a thing happening with a VOIP phone or land > line. > > It's a known thing to dial one number and reach another? Can you provide a link? What do you mean by intercept? In any case, I doubt enormously that anything of the kind happened to me; when I successfully contacted my party in the US via an 877 number, I was told there was a snafu concerning their direct line, a *general* one affecting many customers (who all heard the Englishwoman's recorded voice), as if we might still be in the days of telephone exchanges and manual service and some operator was plugging the ringing cord into an erroneously labelled jack (so instead of connecting people to Major Financial Institution Department 22 people were connected to Bristol Furniture and Storage).
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-22 19:50 +0100 |
| Message-ID | <DxeQx-8ny-5@gated-at.bofh.it> |
| In reply to | #243356 |
On Wednesday, December 22, 2021 09:19:31 AM Curt wrote: > On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > That is a known thing (a telephone intercept of a cell phone call), I > > have found nothing so far about such a thing happening with a VOIP phone > > or land line. > > It's a known thing to dial one number and reach another? On a cell phone yes, but I'd have to google again to find a link, I'll try to do that between now and tomorrow. > Can you provide > a link? See above. > What do you mean by intercept? Well it wasn't a word I originally used, but as I googled, I found reference to that. It seems it can mean (refer) to at least two (slightly) different things; * the thing that law enforcement (and others) can do (legally or not), that is put a wiretap on the "line" (virtual or real) and listen in / record the conversation * the other implied / inferred meaning is that of what I described, that is calling one number and having it be intercepted by another party who might masquerade as the called party. (Somebody on the list pointed out essentially the same thing as a "man in the middle" attack.) I did a little bit of googling ([telephone intercept cell phone]) before sending this to see if I could find a link, but no luck. (It's possible I misunderstood something I saw, but I don't think so.)
[toc] | [prev] | [next] | [standalone]
| From | Philippe LeCavalier <support@plecavalier.com> |
|---|---|
| Date | 2021-12-22 20:00 +0100 |
| Message-ID | <Dxf0e-8qG-9@gated-at.bofh.it> |
| In reply to | #243364 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Dec 22, 2021 at 1:45 PM <rhkramer@gmail.com> wrote: > On Wednesday, December 22, 2021 09:19:31 AM Curt wrote: > > On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > > That is a known thing (a telephone intercept of a cell phone call), I > > > have found nothing so far about such a thing happening with a VOIP > phone > > > or land line. > > > > It's a known thing to dial one number and reach another? > > On a cell phone yes, but I'd have to google again to find a link, I'll try > to > do that between now and tomorrow. > > > Can you provide > > a link? > > See above. > > > What do you mean by intercept? > > Well it wasn't a word I originally used, but as I googled, I found > reference > to that. It seems it can mean (refer) to at least two (slightly) > different > things; > > * the thing that law enforcement (and others) can do (legally or not), > that > is put a wiretap on the "line" (virtual or real) and listen in / record > the > conversation > > * the other implied / inferred meaning is that of what I described, > that is > calling one number and having it be intercepted by another party who might > masquerade as the called party. (Somebody on the list pointed out > essentially > the same thing as a "man in the middle" attack.) > > I did a little bit of googling ([telephone intercept cell phone]) before > sending this to see if I could find a link, but no luck. (It's possible I > misunderstood something I saw, but I don't think so.) > I'd have to say the concept of "intercepting" a VoIP call for Google voice reaches beyond logic; not impossible but certainly not probable since Google voice uses TLS to my knowledge. For this to work, you're implying someone is between you and google and the google voice service doesn't know. Again, I'd say this is more likely to be a case of sim cloning/spoofing based on WFH in that the calls are forwarded to cell phones that have been compromised. This lines up well with the stated fact that the calls randomly get "intercepted" and others go to the legit company in question. To my knowledge, with sim cloning the phone rings simultaneously. So the first one to pick up gets the call.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2021-12-22 20:30 +0100 |
| Message-ID | <Dxftf-nU-5@gated-at.bofh.it> |
| In reply to | #243365 |
Philippe LeCavalier writes: > For this to work, you're implying someone is between you and google > and the google voice service doesn't know. Or someone has cracked either Google Voice or the bank (could be an inside job in either case). -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-12-22 20:10 +0100 |
| Message-ID | <Dxf9T-hI-5@gated-at.bofh.it> |
| In reply to | #243364 |
On 2021-12-22, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > * the other implied / inferred meaning is that of what I described, that is > calling one number and having it be intercepted by another party who might > masquerade as the called party. (Somebody on the list pointed out essentially > the same thing as a "man in the middle" attack.) > I can find no example of this with a cell phone.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-22 20:20 +0100 |
| Message-ID | <Dxfjz-kT-5@gated-at.bofh.it> |
| In reply to | #243366 |
On Wednesday, December 22, 2021 02:02:13 PM Curt wrote: > On 2021-12-22, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > * the other implied / inferred meaning is that of what I described, > > that is > > > > calling one number and having it be intercepted by another party who > > might masquerade as the called party. (Somebody on the list pointed out > > essentially the same thing as a "man in the middle" attack.) > > I can find no example of this with a cell phone. Well, I may have misunderstood something I saw / read, but I do hope to find time to look more thoroughly. Have a good day!
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-23 14:10 +0100 |
| Message-ID | <Dxw13-1YQ-5@gated-at.bofh.it> |
| In reply to | #243366 |
[Multipart message — attachments visible in raw view] — view raw
On Wednesday, December 22, 2021 02:02:13 PM Curt wrote: > On 2021-12-22, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > * the other implied / inferred meaning is that of what I described, > > that is > > > > calling one number and having it be intercepted by another party who > > might masquerade as the called party. (Somebody on the list pointed out > > essentially the same thing as a "man in the middle" attack.) > > I can find no example of this with a cell phone. Somebody yesterday posted about Triggerfish -- I can't find that post immediately. Wikipedia says (about Triggerfish): "Intercepting a cell phone call by a man in the middle attack, if the option is enabled, and the user makes or receives a call."
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-12-23 15:10 +0100 |
| Message-ID | <DxwX7-2yJ-5@gated-at.bofh.it> |
| In reply to | #243373 |
On 2021-12-23, rhkramer@gmail.com <rhkramer@gmail.com> wrote: >> >> I can find no example of this with a cell phone. > > Somebody yesterday posted about Triggerfish -- I can't find that post > immediately. > > Wikipedia says (about Triggerfish): > > "Intercepting a cell phone call by a man in the middle attack, if the option > is enabled, and the user makes or receives a call." > Tracking of a cell phone by a mobile FBI van (Wireless Intercept and Tracking Team) which seeks to locate a cell phone lacking GPS tracking by scanning for its emissions. This first became known for its use in tracking hacker Kevin Mitnick.[1] Intercepting a cell phone call by a man in the middle attack ... https://en.wikipedia.org/wiki/Triggerfish_(surveillance) Other than the FBI stalking a criminal element in an unmarked van parked across the street stuffed with sophisticated electronic equipment, I don't believe this theoretical possibility translates to a worrisome probability of malicious behavior for the R.H. Kramers of the world.
[toc] | [prev] | [next] | [standalone]
| From | harryweaver@tutanota.com |
|---|---|
| Date | 2021-12-23 21:40 +0100 |
| Message-ID | <DxD2y-6aC-17@gated-at.bofh.it> |
| In reply to | #243375 |
24 Dec 2021, 00:07 by curty@free.fr: > On 2021-12-23, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > >>> >>> I can find no example of this with a cell phone. >>> >> >> Somebody yesterday posted about Triggerfish -- I can't find that post >> immediately. >> >> Wikipedia says (about Triggerfish): >> >> "Intercepting a cell phone call by a man in the middle attack, if the option >> is enabled, and the user makes or receives a call." >> > > Tracking of a cell phone by a mobile FBI van (Wireless Intercept and Tracking > Team) which seeks to locate a cell phone lacking GPS tracking by scanning for > its emissions. This first became known for its use in tracking hacker Kevin > Mitnick.[1] > > Intercepting a cell phone call by a man in the middle attack ... > > https://en.wikipedia.org/wiki/Triggerfish_(surveillance) > > Other than the FBI stalking a criminal element in an unmarked van parked > across the street stuffed with sophisticated electronic equipment, I don't > believe this theoretical possibility translates to a worrisome probability of > malicious behavior for the R.H. Kramers of the world. > And I don't think the rhetorical `unmarked van parked across the street stuffed with sophisticated electronic equipment' accurately represents the reality. Some of this equipment will happily reside in a backpack. https://theintercept.com/document/2015/12/17/government-cellphone-surveillance-catalogue/ Cheers! Harry.
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-12-23 22:10 +0100 |
| Message-ID | <DxDvA-6AO-7@gated-at.bofh.it> |
| In reply to | #243384 |
On 2021-12-23, harryweaver@tutanota.com <harryweaver@tutanota.com> wrote: >>> >> >> Tracking of a cell phone by a mobile FBI van (Wireless Intercept and Tracking >> Team) which seeks to locate a cell phone lacking GPS tracking by scanning for >> its emissions. This first became known for its use in tracking hacker Kevin >> Mitnick.[1] >> >> Intercepting a cell phone call by a man in the middle attack ... >> >> https://en.wikipedia.org/wiki/Triggerfish_(surveillance) >> >> Other than the FBI stalking a criminal element in an unmarked van parked >> across the street stuffed with sophisticated electronic equipment, I don't >> believe this theoretical possibility translates to a worrisome probability of >> malicious behavior for the R.H. Kramers of the world. >> > > And I don't think the rhetorical `unmarked van parked across the > street stuffed with sophisticated electronic equipment' accurately > represents the reality. Some of this equipment will happily reside in > a backpack. It wasn't really that "rhetorical" a van because it was precisely the very concrete "mobile FBI van" described on the Wikipedia page the OP referenced. As for the accurate representation of reality, I'm afraid we can only hope, however vainly, that people are capable of determining for themselves who might or might not be an expert in the field. > https://theintercept.com/document/2015/12/17/government-cellphone-surveillance-catalogue/ > > Cheers! > > Harry. > > --
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2021-12-23 22:30 +0100 |
| Message-ID | <DxDOV-6H9-3@gated-at.bofh.it> |
| In reply to | #243385 |
[Multipart message — attachments visible in raw view] — view raw
On 24/12/21 5:03 am, Curt wrote: > > It wasn't really that "rhetorical" a van because it was precisely the > very concrete "mobile FBI van" described on the Wikipedia page the OP > referenced. > > As for the accurate representation of reality, I'm afraid we can only > hope, however vainly, that people are capable of determining for > themselves who might or might not be an expert in the field. > >> https://theintercept.com/document/2015/12/17/government-cellphone-surveillance-catalogue/ >> > The tools listed in the intercept article don't allow interception of actual voice calls. They are intended to perform traffic analysis and test functions. Any competent authority would simply get a warrant (or not) and intercept calls at the exchanges. It's very easy and happens all the time. In conflict countries like Syria and Ukraine you can be certain that 100% of call metadata are recorded and a significant fraction, if not 100%, of voice data recorded for future use. It's not a lot of data on the scale of things. Getting back to the OP, on the scale of likelihood: - zero probability a bad guy was sitting across the street to intercept his phone - zero probability a carrier exchange was compromised by a non-state actor - moderate probability the financial institution PBX was compromised - good probability the OP computer *could* have been compromised - it's relatively easy but may not have happened My working theory is the financial institution PBX was compromised and a small percentage of inbound calls intercepted. It was the OP's bad luck to be one of those. -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Philippe LeCavalier <support@plecavalier.com> |
|---|---|
| Date | 2021-12-24 00:50 +0100 |
| Message-ID | <DxG0p-7VA-1@gated-at.bofh.it> |
| In reply to | #243386 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Dec 23, 2021, 16:27 Jeremy Ardley <jeremy@ardley.org> wrote: > > On 24/12/21 5:03 am, Curt wrote: > > > > It wasn't really that "rhetorical" a van because it was precisely the > > very concrete "mobile FBI van" described on the Wikipedia page the OP > > referenced. > > > > As for the accurate representation of reality, I'm afraid we can only > > hope, however vainly, that people are capable of determining for > > themselves who might or might not be an expert in the field. > > > >> > https://theintercept.com/document/2015/12/17/government-cellphone-surveillance-catalogue/ > >> > > > The tools listed in the intercept article don't allow interception of > actual voice calls. They are intended to perform traffic analysis and > test functions. > > Any competent authority would simply get a warrant (or not) and > intercept calls at the exchanges. It's very easy and happens all the > time. In conflict countries like Syria and Ukraine you can be certain > that 100% of call metadata are recorded and a significant fraction, if > not 100%, of voice data recorded for future use. It's not a lot of data > on the scale of things. > > Getting back to the OP, on the scale of likelihood: > > - zero probability a bad guy was sitting across the street to intercept > his phone > > - zero probability a carrier exchange was compromised by a non-state actor > > - moderate probability the financial institution PBX was compromised > > - good probability the OP computer *could* have been compromised - it's > relatively easy but may not have happened > > My working theory is the financial institution PBX was compromised and a > small percentage of inbound calls intercepted. It was the OP's bad luck > to be one of those. > > -- > Jeremy > > Thank you.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-24 16:00 +0100 |
| Message-ID | <DxUd4-82I-3@gated-at.bofh.it> |
| In reply to | #243386 |
On Thursday, December 23, 2021 04:26:54 PM Jeremy Ardley wrote: > Getting back to the OP, on the scale of likelihood: > > - zero probability a bad guy was sitting across the street to intercept > his phone > > - zero probability a carrier exchange was compromised by a non-state actor > > - moderate probability the financial institution PBX was compromised > > - good probability the OP computer *could* have been compromised - it's > relatively easy but may not have happened I don't think my computer is relevant -- the ObiHai VOIP device is a self contained device -- it doesn't need / use my computer for anything except: * many years ago, iirc, and occasionally since then, I've used it to go to an ObiHai web page to set up the ObiHai device, and specify the "provider" (Google Voice). (Occasionally since then I've had to go back to that page and check or re-setup the device.) * if I want to do things like view the Google Voice phone log, I do that on a web page (on my computer). > > My working theory is the financial institution PBX was compromised and a > small percentage of inbound calls intercepted. It was the OP's bad luck > to be one of those.
[toc] | [prev] | [next] | [standalone]
| From | Philippe LeCavalier <support@plecavalier.com> |
|---|---|
| Date | 2021-12-24 16:20 +0100 |
| Message-ID | <DxUwp-8vj-3@gated-at.bofh.it> |
| In reply to | #243402 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Dec 24, 2021, 09:57 <rhkramer@gmail.com> wrote: > On Thursday, December 23, 2021 04:26:54 PM Jeremy Ardley wrote: > > Getting back to the OP, on the scale of likelihood: > > > > - zero probability a bad guy was sitting across the street to intercept > > his phone > > > > - zero probability a carrier exchange was compromised by a non-state > actor > > > > - moderate probability the financial institution PBX was compromised > > > > - good probability the OP computer *could* have been compromised - it's > > relatively easy but may not have happened > > I don't think my computer is relevant -- the ObiHai VOIP device is a self > contained device -- it doesn't need / use my computer for anything except: > > * many years ago, iirc, and occasionally since then, I've used it to go > to > an ObiHai web page to set up the ObiHai device, and specify the "provider" > (Google Voice). (Occasionally since then I've had to go back to that page > and > check or re-setup the device.) > > * if I want to do things like view the Google Voice phone log, I do > that on > a web page (on my computer). > > > > > > My working theory is the financial institution PBX was compromised and a > > small percentage of inbound calls intercepted. It was the OP's bad luck > > to be one of those. > It's a process. Always work from the most probable to the least. As outlined, google is the least likely and you and devices you control are the most likely. Vet one move on to the next. It's a simple process and as long as you're thorough it's the best approach to draw a solid conclusion. If the device isn't compromised (which, you saying so doesn't in any way vet the device as safe and not compromised btw) then the desktop you got the number from is the next step to vet. What OS are you running, what endpoint security do you have...etc. next after that would be your home network. What router/gateway/firewall do you have? What dns service do you use (could be key imo)? So on and so forth until we find the smoking gun. This would go all the way to speaking with a legit person at the financial firm about their PBX which you will no doubt find huge degrees of resistance. One thing that breaks this process is the user making statements based on previous knowledge or assumption like you just did about your obi device. You have to vet aspects even if you know them to be clean. Your assumption and emotion have no room in this process IF you want to find the truth.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2021-12-24 16:30 +0100 |
| Message-ID | <DxUG5-73-5@gated-at.bofh.it> |
| In reply to | #243405 |
Philippe LeCavalier writes: > If the device isn't compromised (which, you saying so doesn't in any > way vet the device as safe and not compromised btw) then the desktop > you got the number from is the next step to vet. How do you explain the Google Voice log entries? -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Philippe LeCavalier <support@plecavalier.com> |
|---|---|
| Date | 2021-12-24 16:40 +0100 |
| Message-ID | <DxUPL-aa-1@gated-at.bofh.it> |
| In reply to | #243406 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Dec 24, 2021, 10:26 John Hasler <john@sugarbit.com> wrote: > Philippe LeCavalier writes: > > If the device isn't compromised (which, you saying so doesn't in any > > way vet the device as safe and not compromised btw) then the desktop > > you got the number from is the next step to vet. > > How do you explain the Google Voice log entries? > > Yes the legit number was called but randomly (so it appears) a imposter is > answering while other times the legit company answers. That's the > information we know for fact u less I'm mistaken. So if you asked me to draw a conclusion and forego all the investigative steps suggested which I do not recommend, I would say the two most probable causes are a compromised PBX at the financial institute or sim card cloning. Third on the list would be dns poisoning on the OPs gateway. All 3 scenarios would have the log entries look legit.
[toc] | [prev] | [next] | [standalone]
| From | harryweaver@tutanota.com |
|---|---|
| Date | 2021-12-22 21:50 +0100 |
| Message-ID | <DxgIG-12y-13@gated-at.bofh.it> |
| In reply to | #243356 |
-- Sent with Tutanota, the secure & ad-free mailbox. 23 Dec 2021, 00:19 by curty@free.fr: > On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > >> >> That is a known thing (a telephone intercept of a cell phone call), I have >> found nothing so far about such a thing happening with a VOIP phone or land >> line. >> > > It's a known thing to dial one number and reach another? Can you provide > a link? What do you mean by intercept? > > https://en.wikipedia.org/wiki/Triggerfish_(surveillance) > Any number of others. > In any case, I doubt enormously > that anything of the kind happened to me; when I successfully contacted > my party in the US via an 877 number, I was told there was a snafu > concerning their direct line, a *general* one affecting many customers > (who all heard the Englishwoman's recorded voice), as if we might still > be in the days of telephone exchanges and manual service and some > operator was plugging the ringing cord into an erroneously labelled jack > (so instead of connecting people to Major Financial Institution > Department 22 people were connected to Bristol Furniture and Storage). > Yes, there's a cross-connection somewhere. Whether that is hard-wired or wireless is immaterial. It could be brought about by something as innocuous as a short, somewhere. Cheers! Harry
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web